CVE-2026-92522: ACPI: processor: validate MADT IOAPIC entry bounds
Published Sep 17, 2026
·Updated
ACPI: processor: validate MADT IOAPIC entry bounds
Affected Software
2 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.152.1-1<6.6.157.1-1
6.6.157.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Sep 17, 2026
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
DescriptionSeverity
Sep 19, 2026
Data Sourced
via Microsoft·08:07 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:07 AM
DescriptionSeverity
Frequently Asked Questions
1
What condition is required to reach the vulnerable parsing behavior?
The IOAPIC hotplug lookup must process MADT or _MAT ACPI records that are incomplete or whose declared subtable length extends beyond the available record range. A typed IOAPIC record that lacks its complete fixed body can also reach the unsafe field-reading path.
2
Are both MADT and _MAT ACPI table sources relevant?
Yes. The issue affects the MADT walk and the _MAT provider path used by IOAPIC hotplug lookup. The resolved code applies the same record-boundary validation relationship to both paths.